The two questions founders actually ask.
Can my data live on Supabase or Firebase overseas?
Yes, subject to POPIA's transborder rules in section 72: broadly, the recipient
jurisdiction or contract must provide comparable protection, or you need the data
subject's consent, or the transfer must be necessary for the contract with them. In
practice for a startup: sign or accept the platform's data processing terms, choose a
sensible hosting region, disclose the overseas processing in your privacy notice,
and record that reasoning. The platforms are operators in POPIA's terms; you remain
the responsible party. Those terms also move under you, so re-read them when a
platform announces a data change. Lovable is the current worked example: its notice
of 5 August 2026 says that from 9 September 2026 it may use customer content from
Free and Pro plans for AI model training unless you opt out, where customer content
means your prompts and attached files, code, project files, configurations and
generated outputs, and it states that your apps' end-user data is excluded and stays
in your project's own database. So the exposure is not your users' table; it is
whatever you pasted into a prompt to debug it. Two days after that notice Lovable
renamed the control and inverted its label, so read the toggle rather than trusting
a remembered setting name. Our
guide to builder AI-training clauses
covers what each platform says and what to record.
What happens if we leak data?
Section 22: where there are reasonable grounds to believe personal information has
been accessed or acquired by an unauthorised person, you must notify the Information
Regulator and the affected people as soon as reasonably possible, in a form that lets
them protect themselves. Practically: fix the exposure, establish what was reachable
and when, write the timeline down as you go, and take advice on the notification
wording. Discovering your own breach via the checklist is dramatically better than a
researcher or an attacker discovering it for you.